108 Chrome Extensions Just Got Caught Stealing Passwords. Here’s How to Check Yours.
A security team just discovered 108 Chrome browser extensions — from five different publishers — that were quietly stealing Google login credentials, browsing history, and personal data from roughly 20,000 users. These weren’t sketchy-looking downloads. They were ad blockers, QR code tools, emoji keyboards — the kind of thing you install once and forget about.
That “forget about” part is the problem.
Every Chrome extension you install gets permissions. Some just need to read the page you’re on. Others ask for access to your cookies, your login sessions, your browsing history across every site you visit. A QR code generator doesn’t need your Google password. But if you clicked “allow” three years ago, it has whatever you gave it — and you’d never know if the publisher sold out, got hacked, or was sketchy from the start.
Here’s your one thing this morning. Open Chrome. Type chrome://extensions/ in the address bar. Look at what’s there. Anything you don’t recognize? Remove it. Anything you installed years ago and haven’t touched since? Remove it. Anything that asks for permissions that don’t match what it actually does — a coupon clipper that wants access to your camera, a color picker that reads your cookies — remove it.
I just audited my own this morning. Thirteen extensions. Two had more access than they needed. Both are off now.
Your store’s POS login, your vendor portals, your bank — they all live in that browser. An extension with the right permissions can see all of it. Five minutes of cleanup is worth it.
xoxo, ❤️ AmyFay
What’s happening in the world. What it means for your store. Monday through Thursday, from AmyFay Chandler. More in Weekly Retail Tidbits every Friday.